logo

Moonstone Sleet emerges as new North Korean threat actor with new bag of tricks

ID: 652bf5fc-190d-5d40-8dcc-6b56e604ffa6

STIX ID: report--652bf5fc-190d-5d40-8dcc-6b56e604ffa6

Feed Name: Microsoft Security

Threat Score
90/100

Date Published: 2024-05-28

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft identifies Moonstone Sleet, a distinct North Korean state‑aligned threat actor, that leverages trojanized open‑source tools (e.g., PuTTY), malicious npm packages, a weaponized game (DeTankWar), custom loaders (SplitLoader, YouieLoad), credential theft techniques, and a new FakePenny ransomware strain to pursue espionage and revenue generation; the report includes observed compromises, file hashes and domains, detection queries for Microsoft Defender XDR and Sentinel, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.